GreatXML BitLocker Bypass Means TPM-Only Is the Bug (opens in new tab)
If your laptop fleet runs BitLocker in TPM-only mode, the disk on the machine that just got left in a hotel room is now functionally unencrypted to anyone who can hold Shift while clicking Restart. That is the practical reading of GreatXML, a proof-of-concept published June 11, 2026 by a researcher who goes by Nightmare Eclipse (also Chaotic Eclipse, GitHub handle MSNightmare). It drops a SYSTEM shell with full read-write access to the decrypted volume. There is no CVE. There is no patch. Wha...
Read the original article